Deploying Kubernetes on Fedora CoreOS with Kubespray, I hit a Kubespray CRI-O read-only file system error partway through the container runtime install. The fix is one inventory variable.

The failing task:

TASK [container-engine/cri-o : Cri-o | create directory for libexec] ******************
fatal: [worker-03]: FAILED! => {"changed": false, "msg": "There was an issue creating /usr/libexec/crio as requested: [Errno 30] Read-only file system: b'/usr/libexec/crio'", "path": "/usr/libexec/crio"}

Why Kubespray’s CRI-O role fails on Fedora CoreOS Link to heading

Fedora CoreOS mounts /usr read-only, so only OS updates can change it. Kubespray’s CRI-O role sets crio_libexec_dir to /usr/libexec/crio by default and copies conmon, conmonrs, crun and runc into it, so the first task that creates that directory fails.

This comes from Kubespray’s settings for CRI-O 1.31 and later. Older versions installed conmon into bin_dir and never touched /usr/libexec.

Fixing the read-only error with crio_libexec_dir Link to heading

The path is a variable, so I override it in the inventory and point it at somewhere writable:

# inventory/<cluster>/group_vars/all/coreos.yml
crio_libexec_dir: "/opt/libexec/crio"

Re-run the playbook. Kubespray installs the binaries into the new directory and writes the matching conmon and runtime paths into /etc/crio/crio.conf. The crio.service unit doesn’t reference this directory, so it needs no change.

Checking it worked Link to heading

On a node:

grep conmon /etc/crio/crio.conf
systemctl is-active crio

The conmon line should point at /opt/libexec/crio/conmon, and CRI-O should report active.

Related Posts